Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian 7: DLA-1025-1 Critical: Bind9 TSIG Authentication Issues

debian lts
Calendar Grey July 13, 2017
Dist Debian Esm H88
Significant resolution problems in domain name system administration addressed in Debian Long Term Support. Ensure protection from TSIG threats.
CVE-2017-3142 An attacker who is able to send and receive messages to an authoritative

Summary

CVE-2017-3142

An attacker who is able to send and receive messages to an authoritative
DNS server and who has knowledge of a valid TSIG key name may be able to
circumvent TSIG authentication of AXFR requests via a carefully constructed
request packet. A server that relies solely on TSIG keys for protection
with no other ACL protection could be manipulated into:
- providing an AXFR of a zone to an unauthorized recipient
- accepting bogus NOTIFY packets

CVE-2017-3143

An attacker who is able to send and receive messages to an authoritative
DNS server and who has knowledge of a valid TSIG key name for the zone and
service being targeted may be able to manipulate BIND into accepting an
unauthorized dynamic update.


For Debian 7 "Wheezy", these problems have been fixed in version
1:9.8.4.dfsg.P1-6+nmu2+deb7u17.

We recommend that you upgrade your bind9 packages.

Further information about Debian LTS security advisories, how to apply

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: bind9
Version: 1:9.8.4.dfsg.P1-6+nmu2+deb7u17
CVE ID: CVE-2017-3142 CVE-2017-3143

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here